PT-2023-24684 · Unknown · Javacpp Presets

R3X

·

Published

2023-06-08

·

Updated

2023-06-16

·

CVE-2023-34112

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions JavaCPP Presets versions prior to 1.5.9
Description The issue concerns the insecure use of the github.event.head commit.message parameter in JavaCPP Presets, leading to a command injection vulnerability due to string interpolation. No exploitation has been reported.
Recommendations For versions prior to 1.5.9, upgrade to version 1.5.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of the github.event.head commit.message parameter in the affected actions until a patch is applied.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-34112
GHSA-36RX-HQ22-JM5X

Affected Products

Javacpp Presets